BTCPay Server warns bots are probing exposed Lightning nodes for a restart-time flaw
BTCPay Server has warned that malicious bots are actively and repeatedly calling an LND password-change endpoint on Lightning nodes that operators manually re-exposed to the internet, exploiting a brief window right after LND restarts while the wallet is still locked. Version 2.4.4, released on Sept. 7, closes the path by assigning unique random passwords to new LND wallets, rotating passwords on older installations that used the shared default credential, and blocking unauthenticated wallet setup and unlock calls through BTCPay's standard reverse proxy.
If the probing succeeds, an attacker could submit the old shared password before BTCPay's internal unlocker, replace it, and request an administrator macaroon that grants control over the LND node and the merchant wallets it secures — the same end result as the August theft. Anyone running a self-hosted BTCPay Server with a custom reverse proxy or publicly exposed LND is directly exposed and must patch and re-audit their network rules.
The targeted password-change method does not require a macaroon during the post-restart interval, which normally is the credential LND uses to authorize administrative actions, and older BTCPay LND wallets compounded the risk by relying on a shared default password. BTCPay's proxy-side protections cannot secure infrastructure operators configure themselves, so custom reverse proxies remain vulnerable until public LND routes are removed; a route-control change merged Sept. 11 provides a supported remote-access option with LND and Core Lightning interfaces disabled by default. BTCPay has not reported any successful takeover via this newly observed activity and has not linked the bots to the August attackers.
rss · CryptoSlate · · Single source
Background, discussion, and references
Market impact
The transmission channel here is custody and infrastructure risk rather than Bitcoin's protocol: merchant funds held in Lightning channels on self-hosted LND nodes are the exposed asset, and sustained probing could push some self-hosted merchants toward hosted payment processors or managed node services. In the broader market, the effect is sentiment-level for Bitcoin and Lightning-related infrastructure, as repeated incidents at a widely used merchant toolchain may weigh on merchant willingness to run Lightning nodes themselves.
Background
BTCPay Server is a self-hosted, open-source Bitcoin payment processor that lets merchants accept BTC directly without a third-party gateway, and it commonly runs alongside LND, the Lightning Network implementation developed by Lightning Labs that enables fast, low-fee off-chain payments. Administrative access to LND is governed by macaroons, small signed tokens that assert which actions a client is allowed to perform on the node. On Aug. 7, BTCPay acknowledged that attackers had exploited a flaw affecting all versions before 2.4.2 to obtain LND macaroon files unauthenticated and move funds, after which the project disabled external access to LND in its standard Docker deployment, offered a recovery bounty capped at 3 BTC, and involved exchanges, analytics firms, and law enforcement in tracing the stolen bitcoin.
References
Tags
#security#bitcoin#lightning-network#btcpay#vulnerability